Dear all,
currently our jira service desk is availavle over the world-wide-web.
Internal vulnerability scans showed that cve-2022-22970 / cve-2022-22971 is affected to the current installed JIRA SD 4.20.11 version.
| /opt/atlassian/jira/atlassian-jira/WEB-INF/lib/spring-core-5.3.19.jar |
Is it anyhow planed to fix this issue?
Do you have any workaround?